Compliance Features Overview

  • Updated

The Compliance Features area in OWL helps organizations protect sensitive information and manage records in accordance with applicable laws, regulations, and internal policies. These capabilities support consistent record handling throughout the record lifecycle, from classification and access control through retention, legal hold, and disposition.

Compliance features are available according to the organization’s licensed OWL edition and enabled modules.

Compliance Features help organizations:

  • Support federal, state, and organization-specific compliance requirements.
  • Protect sensitive and restricted information from unauthorized access.
  • Apply consistent record-handling rules across departments.
  • Reduce manual administration through configured workflows and notifications.
  • Maintain a clear, complete audit history of record and compliance activity.
  • Improve data governance, security, and accountability.

Together, these compliance features enable organizations to securely manage sensitive information while ensuring records remain protected, auditable, and compliant throughout their lifecycle.

Compliance capabilities at a glance

Feature Purpose
Juvenile Compliance Identifies and applies additional handling controls to records involving juvenile subjects.
28 CFR Part 23 Compliance Supports criminal intelligence record-management requirements for organizations subject to 28 CFR Part 23.
Retention Policies Defines how long supported records are retained and when they are archived or moved to Trash for permanent disposition.
Legal Hold Prevents a record from being archived, deleted, or otherwise disposed of while it is subject to a legal, regulatory, audit, or investigative requirement.
Data Classification and Access Rights Applies classification and access controls to help ensure sensitive records are visible only to authorized users.
Audit Logging Records user and system actions to provide a complete history of record and compliance activity.
Compliance Notifications Sends configured notifications for relevant compliance events, such as reviews, status changes, or retention lifecycle actions.

Juvenile Compliance

Juvenile Compliance provides enhanced protection for records that involve juvenile subjects. When enabled and applicable, OWL can identify a subject as a juvenile using the organization’s configured criteria, such as date of birth and jurisdictional age requirements.

The organization can apply additional access restrictions and handling rules to help ensure juvenile information is viewed and managed only by authorized users. Juvenile status and related compliance activity are recorded in the subject’s history.

See Juvenile Compliance for more information.

28 CFR Part 23 Compliance

28 CFR Part 23 applies to criminal intelligence systems operated by state, local, and tribal law-enforcement agencies. In OWL, this feature helps an organization manage intelligence information according to its configured review, validation, dissemination, and purge requirements.

Organizations that use this feature can configure the applicable workflows and review requirements for their environment. Users should follow their agency’s established policies when creating, reviewing, sharing, or disposing of criminal intelligence information.

See 28 CFR Part 23 for more information.

Retention Policies

Retention Policies define how long a supported record must be kept and what happens at the end of its lifecycle. A policy can include an archive date, a delete date, or both.

  • On the archive date, the record becomes read-only.
  • On the delete date, the record moves to Trash for the configured recovery period.
  • After the recovery period, the record is permanently deleted and cannot be restored.

For linked records, the OWL Compliance setting determines whether the linked record follows the parent record’s compliance and retention policy or retains its own compliance and retention policy.

See Understanding the Records Retention Policy Lifecycle for details.

Legal Hold

Legal Hold protects a record that may be relevant to litigation, a regulatory inquiry, an audit, or an investigation. While a Legal Hold is active, the record cannot be archived, deleted, or permanently disposed of through the retention lifecycle.

Only authorized users can apply or release a Legal Hold. The hold and any related actions are recorded in the audit history.

Data Classification and Access Rights

Data Classification and Access Rights help organizations identify sensitive information and limit access based on a user’s authorized role, clearance, or assigned access level.

For example, an organization may classify records as Public, Internal, Confidential, or Restricted. The available classification levels and access rules are defined by the organization. OWL then applies the configured access controls when users attempt to view or work with those records.

See Classification & Access Rights for more information.

Audit Logging

OWL logs record and compliance activity to provide accountability and traceability. Depending on the action, audit history can record details such as the record involved, the action taken, the user or system process that performed it, and the date and time.

Examples of auditable activity include:

  • Creating or updating a record
  • Changing a classification, access right, retention policy, or Legal Hold
  • Archiving, moving to Trash, restoring, or permanently deleting a record
  • Completing a compliance-related review or workflow action
  • Updating user roles, permissions, or record ownership

Compliance Notifications

OWL can provide notifications for configured compliance events. Examples may include an upcoming review date, a record’s archive or delete date, a retention lifecycle action, or a change that requires attention from an authorized user.

Notification recipients and timing depend on the organization’s enabled features and configuration.

Important considerations

  • The compliance features available to a user depend on the organization’s licensed OWL edition, enabled modules, and assigned permissions.
  • Organization policies and applicable laws determine how each feature should be configured and used.
  • Legal Hold and other applicable governance controls take precedence over actions that would archive, delete, or permanently dispose of a record.